A bed for the vault: redis's password as a secret it provides, rotated

Design 13's three logins, for a secret that had no owner before (novox/hq
ADR 0085): the delivered password authenticates against the real redis, the
one `rotate secret` delivers authenticates, and the one rotated away is
refused. Plus the owner's half: the vault's ledger names the holder and the
fingerprint, notices the rotation, and answers over the mesh by fingerprint,
never by value. Runs the catalogue's own manifests.
This commit is contained in:
2026-09-21 00:01:50 +02:00
parent a43e6d2927
commit 639175ec4a
2 changed files with 456 additions and 0 deletions
+32
View File
@@ -0,0 +1,32 @@
# One machine that becomes a mesh and then assigns itself mesh-vault and redis — a provider whose own
# password is a `secret` the vault provides (novox/hq ADR 0085, design 24).
#
# redis-node proves a provider's runtime. This proves the vault: redis requires `secret`, the mesh
# mints the pair credential, the host fills redis.conf from it, redis authenticates with it, and the
# vault's ledger records its fingerprint. Then `rotate secret` moves both ends: the new password
# works, the old one is refused, and the vault says it was rotated — design 13's three logins, for a
# secret that had no owner before.
scenario: vault-node
segments:
hosting:
kind: public
cidr: [192.0.2.0/24]
machines:
anchor:
at: { segment: hosting, address: [192.0.2.10] }
egress: true
inbound: allow
memory: 3GiB
cpus: 2
images:
- mesh-controller:development
# Built by scripts/build-module-runtime.sh mesh-vault / redis into the local daemon; the machine holds
# each by its own image ID. redis's server image is pulled upstream by digest.
- mesh-runtime-mesh-vault:development
- mesh-runtime-redis:development
place:
all: [host, runtime]